certslothcertsloth
CCSP/Topic 11

ISC2 / Professional

Cloud Responsibilities and Provider Assurance

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Outsource the operation; retain the accountable decision.

Must remember

Map responsibilities for each service, not just the provider's brand. In IaaS the customer normally manages guest operating systems and applications; PaaS shifts more runtime work to the provider; SaaS shifts application operation too. Identity, data use, tenant settings and legal accountability remain relevant in all models.

Cloud characteristics include self-service, broad access, pooled resources, elasticity and measured consumption. Public, private, hybrid, community and multicloud describe deployment/ownership arrangements, not automatic security levels. A broker may coordinate services while a regulator imposes obligations; neither replaces the customer/provider responsibility matrix.

Assess the control plane separately from workloads. An API credential that changes IAM, logging or encryption settings may bypass application defenses. Use strong authentication, scoped roles, separation of duties, immutable deployment patterns and protected audit trails. Multitenancy requires isolation of compute, networking, storage and operational access.

Evaluate provider evidence against the exact service, region, control scope and review period. Common Criteria evaluates a defined product/security target; FIPS validation addresses a cryptographic module boundary; neither certifies the customer's whole deployment. Provider audit reports often specify customer controls that must still be implemented.

Portability moves data/workloads; interoperability makes systems work together; reversibility supports exit from a service. Plan export formats, egress cost, key ownership, identity transition, backups and deletion evidence before lock-in becomes an emergency.

Continuity must include provider outages, account compromise, inaccessible keys and regional dependencies. Test RPO/RTO against the whole service chain. Confidential computing can protect selected data-in-use scenarios; it does not eliminate malicious application logic or poor authorization.

Choose under exam pressure

Requirement Choice and reason
Compare two providers Use defined requirements and scoped evidence rather than marketing labels.
Administrator could disable audit Separate logging administration and protect retained copies.
Plan a future exit Test data export, restoration and identity/key transition.

Traps

  • Provider compliance does not automatically make the tenant compliant.
  • A private cloud can still have weak controls and shared failure points.

Active recall

1. What changes across IaaS/PaaS/SaaS?

The division of operational duties, which must be mapped to each actual service.

2. What does FIPS module validation not establish?

Security of the entire application or cloud tenant.

3. Why protect the management plane?

It controls identities, configuration and safeguards for many workloads.

4. Portability versus interoperability?

Portability moves a workload/data; interoperability lets systems cooperate.

5. Why test cloud exit?

Contract promises do not prove exports, keys and target systems will support recovery.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.